Lewati ke isi

Scola V1 Production Baseline — Release Quality Gate

Scope note (2026-09-04): QG-01–QG-18 di dokumen ini tetap menjadi kontrak sertifikasi release. Metadata SHA dan hasil gate bertanggal 2026-08-08 atau setelahnya adalah evidence historis, bukan pernyataan runtime terkini. Program penyusunan manual memakai Documentation Confidence Gates di bawah dan tidak mengubah verdict release.

Metadata dan status dokumen

Item Nilai
Nama baseline Scola V1 Production Baseline
Mode audit Server development; static repository audit, bukan runtime certification
Workspace /home/scola/odoo
Frontend baseline scola-fe-v2 develop @ 68b77d88f78b3d32f0ede3a54b665e067b014062
Backend baseline custom_addons_scola/gcgscola main @ 2ff6ac7cb41810bbc3b66821cdad004b52d1658a
Tanggal audit 2026-08-08 UTC
Status saat ini Belum mencapai baseline; kriteria di bawah adalah kontrak gate yang diusulkan, bukan bukti bahwa sistem telah lulus

Delta backend e749832/2ff6ac7 mengeraskan beberapa boundary ACL/elevation dan test topology, tetapi belum memiliki bukti runtime yang menutup blocker produk. Karena itu, keberadaan kode, route, menu, test file, status launch_wave_a, atau user guide lama tidak dihitung sebagai bukti lulus. Pemisahan install, entitlement, dan akses UI juga memang merupakan tiga kontrak berbeda (docs/modular/product-tier-and-feature-flags.md:19-31).

Dokumen ini harus dibaca bersama:

Documentation Confidence Gates

Gate ini menjawab apakah satu surface cukup dipahami untuk didokumentasikan dengan aman. Ia tidak mengizinkan deploy dan tidak menggantikan QG-01–QG-18.

Gate Syarat lulus Bukti minimum
DCG-01 — Governance Jenis dokumen, canonical location, owner, audience, status, last verified, dan review date jelas. Inventory dokumen dan approval Documentation Owner.
DCG-02 — Denominator/IA App, menu, canonical route, component, duplicate/internal/obsolete disposition lengkap. Current-tree route/menu inventory dan inbound-link map.
DCG-03 — End-to-end trace UI action dapat ditelusuri ke service, endpoint, controller/model, state, side effect, dan downstream consumer. Source references; tidak ada lompatan yang diisi dengan asumsi.
DCG-04 — Authority/scope Role, capability, assignment, company/record scope, entitlement, dan direct API behavior diketahui. FE/BE trace serta positive/negative scope evidence yang proporsional.
DCG-05 — Business semantics Actor, prerequisite, state transition, completion, correction, exception, notification, dan recovery disahkan. Dated owner decision; inference dari code tidak cukup.
DCG-06 — Runtime confidence Langkah kritis cocok dengan served profile/tenant/candidate yang disebut. Runtime identity, fixture/profile, run ID, result, dan timestamp.
DCG-07 — Safety/supportability Security, privacy, idempotency/retry, data integrity, monitoring, troubleshooting, dan escalation cukup untuk instruksi aman. Review Security/DPO/Ops/Support sesuai risiko.
DCG-08 — Publication Artikel lulus schema, terminology, link/anchor, duplicate, privacy, accessibility, dan role walkthrough. Automated checks + accepted walkthrough tanpa required skip.

Hasil per surface

Status Arti
DISCOVERY Denominator atau trace belum lengkap.
READY_TO_DRAFT DCG-01–DCG-05 lulus; draft internal boleh dibuat.
READY_TO_PUBLISH DCG-01–DCG-08 lulus untuk audience/profile yang disebut.
BLOCKED Ada gap yang membuat instruksi tidak aman, menyesatkan, atau tidak dapat diselesaikan.
SUPERSEDED Tidak lagi aktif; memiliki canonical replacement atau archive disposition.

Aturan agregasi: status domain adalah status terendah dari seluruh artikel wajib dalam denominator-nya. Artikel aman dapat diterbitkan lebih dahulu, tetapi surface BLOCKED harus tetap tampak dan tidak boleh dihitung sebagai PASS. Tidak ada persentase global sebelum denominator dibekukan.

Closure minimum untuk dokumentasi

Temuan prosedural release-readiness hanya menahan dokumentasi bila memengaruhi kebenaran atau keamanan instruksi. Wajib ditutup sebelum publish:

  • route/menu/component atau istilah kanonis belum diketahui;
  • role/capability/company/record scope masih berpotensi memberi instruksi akses salah;
  • mutation, state, side effect, retry, correction, atau recovery ambigu;
  • privacy, credential, attachment, biometric, finance, payroll, atau student data handling belum aman;
  • runtime/profile yang menjadi dasar langkah tidak dapat disebutkan;
  • artikel lama yang bertentangan masih tampil sebagai SSOT aktif.

Residual release evidence, full-catalog regression, atau non-critical polish tidak menahan artikel yang surface-nya sendiri telah memenuhi DCG. Hal tersebut tetap tercatat pada QG/backlog dan tidak boleh dianggap selesai.

1. Makna baseline

Scola V1 Production Baseline tercapai hanya jika satu snapshot produk yang spesifik telah:

  1. disetujui batas paket dan workflow-nya;
  2. memiliki satu entry point menu dan route kanonis untuk tiap tugas pengguna;
  3. menerapkan role capability + record scope + tenant/company scope + domain ownership secara deny-by-default pada UI dan API;
  4. lulus journey positif, negatif, scope, isolasi tenant, validasi, transisi, retry, recovery, propagasi lintas role, integrasi, dan UI sesuai matriks;
  5. tidak memiliki defect atau keputusan terbuka yang dilarang oleh gate; dan
  6. direkam sebagai build frontend, backend, database, module set, entitlement, serta evidence run yang eksak.

Baseline bukan label untuk branch yang “terlihat bekerja”. Ia adalah hasil sertifikasi satu build terhadap satu tenant QA deterministik. Existing QC memang mewajibkan lint, capability check, timezone check, type check, unit/contract test, build, dan E2E untuk perubahan auth/routing/core flow (docs/ai-guidelines/development-guide.md:339-374), sedangkan perubahan backend mewajibkan unit/boundary checks, module upgrade, dan health check (docs/ai-guidelines/development-guide.md:377-420). Gate di sini menambahkan bukti produk dan runtime yang belum tercakup hanya oleh exit code CI.

2. Disposition yang diizinkan

Disposition Arti Dampak terhadap baseline
Release Blocker Defect, keputusan, atau evidence gap dapat memberi akses tidak sah, kebocoran lintas tenant, korupsi data, workflow inti gagal, atau klaim produk tidak benar. Baseline tidak dapat disetujui.
Must Fix Ketidaksesuaian dalam supported contract yang material tetapi tidak langsung memenuhi definisi Release Blocker. Harus ditutup sebelum baseline; tidak boleh sekadar diberi warning.
Accepted Limitation Batas perilaku non-kritis yang eksplisit, sempit, dapat diuji, disetujui owner, memiliki workaround aman dan tanggal tinjau. Dapat lulus hanya dengan approval dan evidence limitation.
Post-release Improvement Polish atau perluasan di luar kontrak V1 yang tidak mengganggu keselamatan, correctness, akses, task completion, atau supportability. Tidak menghambat baseline; tetap memiliki owner dan target.

2.1 Hal yang tidak boleh menjadi Accepted Limitation

  • bypass capability, record rule, atau tenant/company scope;
  • akses student/parent/sensitive record di luar relasi sah;
  • mutasi elevated tanpa ownership dan audit attribution;
  • korupsi, duplikasi, atau kehilangan data;
  • transisi status inti yang ambigu atau tidak dapat dipulihkan;
  • workflow inti tanpa correction/reversal atau recovery yang disetujui;
  • menu visible tetapi API forbidden, atau route hidden tetapi mutation dapat dipanggil tanpa otorisasi setara;
  • privacy control, retention, consent, attachment ownership, atau proof-file validation yang belum aman; dan
  • test wajib yang skipped, quarantined, flaky tanpa root cause, atau hanya lulus dengan superadmin.

Aturan ini menahan normalisasi defect yang sudah dikonfirmasi, misalnya active-role semantics dan capability shadowing (docs/documentation-planning/documentation-blockers.md:92-114), serta W05 first-save, roster integrity, correction, state, dan proof privacy (docs/documentation-planning/documentation-blockers.md:296-354).

3. Aturan hasil dan evidence

3.1 Status eksekusi

Setiap test case hanya boleh memiliki satu status:

Status Dihitung lulus? Ketentuan
PASS Ya Assertion dan evidence lengkap pada build yang disertifikasi.
FAIL Tidak Hasil aktual berbeda dari kontrak.
BLOCKED Tidak Prasyarat, keputusan, atau defect belum ditutup.
NOT RUN Tidak Belum dieksekusi pada build target.
SKIPPED Tidak Skip adalah evidence gap, bukan keberhasilan.

Retry otomatis tidak boleh mengubah FAIL menjadi PASS tanpa menyimpan attempt awal dan alasan retry. Test flaky tetap open defect sampai deterministik atau secara formal dikeluarkan dari supported contract.

3.2 Minimum evidence per test run

Setiap run menyimpan:

  • baseline ID, UTC start/end, runner, environment, dan test-matrix ID;
  • exact FE SHA, BE SHA, database snapshot/seed version, installed addon versions, feature flags, entitlements, serta active company;
  • fresh-role account fixture dan assignment fixture yang dipakai; credential tidak boleh disimpan dalam evidence;
  • route, request/API, expected/actual status, assertion, dan cleanup/reset result;
  • trace/log ID yang aman, screenshot hanya bila membantu UI proof, serta redaksi PII/secrets;
  • defect ID untuk setiap FAIL, blocker/decision ID untuk setiap BLOCKED; dan
  • reviewer serta approval record.

Evidence yang hanya berasal dari akun superadmin tidak sah untuk normal E2E. Golden Tenant harus menyediakan fresh-role account; kebutuhan ini sudah muncul dalam keputusan runtime fixture (docs/documentation-planning/decision-workshop.md:111-118).

4. Gate wajib

Semua gate bertanda 100% berarti seluruh item in-scope berstatus PASS pada build yang sama; tidak ada denominator yang dikecilkan setelah eksekusi. Optional package disertifikasi terpisah dan tidak dapat “menumpang hijau” pada SC-CORE.

Gate Kriteria lulus terukur Evidence minimum Jika gagal Evidence repository
QG-01 Product contract 100% app, addon, menu group, dan W00–W20 memiliki satu status eksklusif; semua Core V1, Optional Supported, dan Controlled Pilot memiliki SKU/owner/role/shell/menu/route/addon/dependency/maturity/blocker; certified jenjang/timezone profiles and exclusions are explicit; PO, Commercial, Security, dan Operations menyetujui scope. Signed 01, decision log, package/profile manifest. Release Blocker Candidate audit mencakup 36 app, 67 manifest addon, 4 no-manifest directory, 143 menu group, dan 20 domain workflow candidates (docs/documentation-planning/product-surface-candidates.md:420-430); W00 is the separately normalized platform prerequisite; profile branching exists in src/config/schoolJenjang.js:5-13; status/profile candidates belum persetujuan final.
QG-02 Canonical IA Setiap supported user task mempunyai tepat satu menu/route kanonis per role; seluruh alias hanya redirect teruji; 0 unsupported/legacy/placeholder leaf terlihat; 0 dead link, visible-but-forbidden, atau hidden-but-unguarded route. 02 closed, automated route/menu crawl per role, manual breadcrumb/name review. Release Blocker untuk inaccessible/exposed surface; Must Fix untuk naming-only issue. Apps/menu adalah SSOT yang diharapkan (docs/ai-guidelines/menu-architecture.md:1-18); current audit menemukan alias/menu/permission drift (docs/documentation-planning/documentation-blockers.md:370-380) dan placeholder/register (docs/documentation-planning/documentation-blockers.md:284-294).
QG-03 Authorization contract 100% supported routes dan mutations dipetakan ke capability atomik, record scope, tenant/company scope, domain owner, dan audit actor; backend deny-by-default; UI availability sama dengan API authority; multi-role/active-role semantics disetujui. Signed 04, route-to-controller matrix, positive/negative tests, elevation inventory. Release Blocker Active role bukan bukti backend union dan prefix resolution dapat shadow (docs/documentation-planning/documentation-blockers.md:92-114); same-origin tidak menggantikan authorization (docs/ai-guidelines/architecture-api.md:1-20).
QG-04 Golden Tenant determinism Seed Scola Golden School dari kosong dan reset berhasil tiga kali berturut-turut dengan fixture IDs/logical keys konsisten; tidak bergantung pada superadmin/akun warisan; second tenant tersedia untuk isolation; every certified jenjang/timezone equivalence class has a named deterministic profile and cannot borrow another profile's PASS. Versioned seed/reset/profile manifest, checksums, three run logs per retained profile, fixture inventory dari 06. Release Blocker Runtime baseline, representative accounts, and profile matrix belum dibuktikan (docs/documentation-planning/documentation-blockers.md:80-90; docs/documentation-planning/decision-workshop.md:111-118; DEC-013).
QG-05 Critical E2E completion 100% test wajib untuk seluruh Core V1 workflow lulus pada build target. Dependency chain W00 → W01 → W02 precedes W05 when its pilot/release scope is approved; W16 may execute after W00 in parallel with W01/W02/W05 because it has no proven dependency on them; every other core journey follows only its cataloged prerequisites and reaches business completion with a clean reset. 05, 07, machine-readable results dan runtime traces. Release Blocker W01 menjadi prerequisite lintas attendance/LMS/reporting, while W16 is independent after W00; W00/W02/W05 have different readiness (docs/documentation-planning/documentation-priority.md:79-84; docs/release-readiness/05-e2e-workflow-catalog.md:55-81).
QG-06 RBAC negative tests 100% route dan mutation supported memiliki sekurang-kurangnya satu unauthorized-role denial; high-risk mutation juga menguji capability view-only, direct API call, forged active role, dan multi-role conflict. Expected denial tidak mengubah data. RT-* negative cases, before/after DB assertions, HTTP/Odoo error contract. Release Blocker View/manage mutation drift telah dikonfirmasi pada payroll, kesiswaan, accounting, SPMB, dan settings (docs/documentation-planning/documentation-blockers.md:140-174,224-234,272-282).
QG-07 Record and tenant isolation 100% sensitive/read/write endpoints menguji own-scope, other assignment/class/child, other school/company, and guessed ID; seluruh unauthorized case denied dan payload tidak bocor existence/PII. Two-company Golden Tenant cases, query/audit traces, no-change assertions. Release Blocker Existing findings mencakup fee enrollment, messaging membership, calendar owner/company, Dapodik identity, dan W05 roster scope (docs/documentation-planning/documentation-blockers.md:200-210,236-270,308-318).
QG-08 Validation and integrity 100% required field, format, boundary, duplicate, stale version, partial roster, and attachment constraints have frontend feedback and authoritative backend rejection; mutation atomic or safely resumable; no orphan/duplicate/cross-owner record. Validation cases, transaction/rollback assertions, model constraints, concurrency/idempotency cases. Release Blocker untuk integrity/security; Must Fix lainnya. W05 regular save tidak menegakkan exact roster/completeness (docs/documentation-planning/documentation-blockers.md:308-318); BOS/RKAS idempotency/attachment ownership juga belum aman (docs/documentation-planning/documentation-blockers.md:188-198).
QG-09 State, correction, and recovery Setiap critical workflow memiliki approved state glossary/transition matrix; invalid transitions 100% denied; correction/reversal menyimpan actor/time/reason; interruption/retry tidak menggandakan efek; supported recovery lulus. State-machine tests, audit assertions, retry/fault injection, signed owner decisions. Release Blocker W05 menyimpan langsung done, bebas diedit tanpa correction contract, dan Sakit collapse ke Izin (docs/documentation-planning/documentation-blockers.md:320-342); correction decision masih open (docs/documentation-planning/decision-workshop.md:55-69).
QG-10 Cross-role and cross-module propagation Untuk setiap declared downstream effect, producer output muncul tepat pada authorized consumer, tidak muncul pada unauthorized consumer, dan update/correction terpropagasi sesuai SLA/notification contract; every bridge has an integration test. Paired producer/consumer assertions, integration IDs, notification delivery/failure evidence. Release Blocker untuk core chain; Must Fix untuk optional package. Install/entitlement/UI adalah lapisan terpisah and bridge modules tidak memiliki UI sendiri (docs/modular/product-tier-and-feature-flags.md:19-31,75-83); notification ownership masih keputusan terbuka (docs/documentation-planning/decision-workshop.md:79-85).
QG-11 Security and privacy 0 open finding yang memungkinkan cross-tenant/assignment access, sensitive attachment exposure, unrestricted elevation, missing audit attribution, consent/retention ambiguity pada supported flow; DPO/security sign-off untuk PII evidence. Threat-boundary checklist, route tests, attachment policy tests, sudo/route budget results, DPO approval. Release Blocker Proof attendance tidak divalidasi dan raw file mengalir ke parent payload (docs/documentation-planning/documentation-blockers.md:344-354); controller .sudo() harus dibatasi capability dan scope (docs/ai-guidelines/development-guide.md:430-443).
QG-12 UX interaction contract 0 Release Blocker/Major issue terbuka pada supported pages; required/error/loading/empty/save/cancel/confirm/toast/table/status terminology konsisten; supported viewports dan keyboard/focus behavior lulus; destructive action selalu consequence-aware. Closed 03, component/UI tests, manual responsive/accessibility run. Release Blocker untuk unsafe/misleading action; Must Fix untuk major issue. Active UI standards define shared page/header and mobile-responsive patterns (docs/ai-guidelines/ui-design-pattern.md:1-35); datetime conversion must remain service-boundary consistent (docs/ai-guidelines/datetime-timezone.md:1-24).
QG-13 Regression suite 100% required FE/BE unit, contract, modular boundary, E2E, package, and changed-code gates exit 0 on release candidate; 0 skipped required case; rerun after last code/schema/module change. CI/server logs tied to SHAs; coverage mapping to 07. Release Blocker Current mandatory commands are enumerated in docs/ai-guidelines/development-guide.md:339-420.
QG-14 Package topology and E2E separation SC-CORE and every enabled optional SKU have distinct test selection/results and an approved exact dependency/auto-install closure; no undeclared peer-SKU hard dependency remains. Installed module does not imply entitlement: enabling one package cannot expose another package's menu, route, capability, API, or data. Composite bridges are certified separately and cannot substitute for either parent certificate. Fresh-database installed-module closure per bundle, approved package manifest, per-SKU/composite suite manifest, entitlement matrix, off/on and direct-API denial tests. Release Blocker. Current manifests contradict independent boundaries across Core/People, Admission/Fees, Report/Student/Assessment, Learning/Report, Assessment/Report, Dapodik/Report, BOS/Leadership/Foundation/valuation, and the enterprise umbrella (01 §8); test:e2e:smoke:core also invokes SPMB (package.json:36).
QG-15 Deployment and schema parity All changed addons upgraded on target DB; module install/upgrade completes; health, worker/cron dependencies, same-origin API, and served frontend bundle pass; no restart-only schema deployment. Upgrade logs, module state/version list, health/API smoke, served index.html/version/assets hashes. Release Blocker Upgrade is mandatory because restart does not create columns (docs/ai-guidelines/development-guide.md:409-415); production helper runs -u before restart (../custom_addons_scola/gcgscola/scripts/ops/upgrade-odoo-prod-modules.sh:1-40).
QG-16 Defect and decision closure 0 open S0/S1; 0 unresolved decision affecting auth, tenant/privacy, state, ownership, supported surface, critical correction/recovery, or completion criteria; every S2/S3 has valid disposition. 08, signed decision register, accepted-limitation log. Release Blocker Existing blocker register still contains 23 Blocker A and 11 Blocker B (docs/documentation-planning/documentation-blockers.md:37-73); workshop contains unresolved product/security/operations decisions (docs/documentation-planning/decision-workshop.md:31-127).
QG-17 Release manifest and reproducibility Exact release manifest complete; fresh environment can install/seed/build/test from recorded inputs; two independent runs reproduce the same contract result. Manifest in §7, install/seed logs, artifact checksums, two run IDs. Release Blocker Static route/code presence was explicitly insufficient for the prior baseline (docs/documentation-planning/documentation-blockers.md:80-90).
QG-18 Freeze for documentation Product, route/menu, role/capability, state, field/action, API effect, and limitation contracts are frozen; all facts intended for documentation map to passing evidence; changes after freeze trigger impact review. Signed source-of-truth snapshot, traceability export, change-control owner. Release Blocker for documentation start; does not by itself block an engineering pre-release build. Existing guides can drift from HEAD, as demonstrated by W05 (docs/documentation-planning/documentation-blockers.md:406-416).

5. Workflow certification rule

A workflow is GREEN — release-ready only when all of these are true:

  1. product status is approved supported scope, not Requires Product Decision;
  2. prerequisites and owners are approved;
  3. canonical menu/route and all API chains are fixed;
  4. every mandatory test category in 07 passes;
  5. all its Release Blocker/Must Fix items are closed;
  6. correction/recovery and downstream visibility pass; and
  7. evidence references the exact release manifest.

Passing the happy path alone is insufficient. A workflow with working read pages but unsafe mutation remains blocked. W05 is the canonical example: the attendance domain/read hub may belong to core, while its write/completion/correction journey cannot be certified until BLK-A19–A23 and related decisions are closed (docs/documentation-planning/product-surface-candidates.md:338-346,406-412).

5.1 Package certification rule

  • SC-CORE must pass independently with optional package flags off.
  • An Optional Supported SKU gets its own certificate on top of a passing Core baseline and all declared prerequisites.
  • Controlled Pilot may run only in named tenants/users with kill switch, telemetry, support owner, rollback, expiry/review date, and pilot-specific gate; it is not GREEN for general release.
  • Legacy / Deprecated, Internal Platform, Incomplete / Remove from Product Surface, and undecided items are excluded and must be invisible/unreachable to normal supported roles.

6. Defect and decision policy

6.1 Severity versus disposition

Severity in 08 describes impact:

  • S0 Critical: exploitable/widespread security, privacy, tenant isolation, or unrecoverable data-integrity/release failure;
  • S1 High: supported critical workflow or authorization boundary materially fails;
  • S2 Medium: bounded functional/consistency failure with safe recovery; and
  • S3 Low: minor polish or low-risk maintainability issue.

Disposition describes release treatment. S0/S1 are always Release Blocker. S2 is normally Must Fix and may become Accepted Limitation only under §2.1. S3 may be Must Fix, Accepted Limitation, or Post-release Improvement based on contract impact. An unresolved product decision is not assigned bug severity; it is a decision gate linked to affected implementation/test units.

6.2 Required closure record

Every closed defect requires:

  • root cause and affected contract;
  • code/config/schema change references;
  • positive and negative regression IDs;
  • before/after result on Golden Tenant;
  • security/DPO review where applicable; and
  • confirmation that no legacy/duplicate route remains exposed.

Every decision requires owner, date, selected option, rejected alternatives, rationale, affected packages/workflows, migration/compatibility treatment, and acceptance-test delta. Engineering may recommend a default but may not silently turn that default into product policy.

7. Exact release manifest

The release candidate is not auditable until one immutable manifest records:

Area Required fields
Baseline Baseline ID, semantic release/version, UTC freeze time, approvers, contract revision.
Frontend Repository, branch, commit SHA, clean-tree assertion, lockfile checksum, Node/npm versions, production build ID, dist checksum, served index.html/version/critical asset checksums.
Backend Repository, branch, commit SHA, clean-tree assertion, Python/Odoo versions, addon paths, changed-addon list, module manifest versions, dependency graph result.
Database Environment/tenant ID, sanitized DB fingerprint, schema/module-upgrade run ID, installed addon names/states/versions, seed/reset version; never credentials or PII dump.
Product Approved SKUs, bundle profiles, entitlements, feature flags, company configuration, supported roles, controlled-pilot allowlist.
Runtime Service/config revision without secrets, workers/cron/queue dependencies, same-origin host mapping, timezone/locale, object/file storage dependency.
Tests Test matrix revision, CI/server run IDs, command list, result counts by status/category/package/workflow, failure/skip list, artifact checksums.
Risk Open S2/S3 list, accepted limitations with owner/expiry, post-release items, rollback trigger and owner.
Operations Backup/restore proof, deployment/upgrade log, health/smoke result, monitoring and rollback references.

The existing production upgrade helper defaults to a specific config/database and supports environment overrides (../custom_addons_scola/gcgscola/scripts/ops/upgrade-odoo-prod-modules.sh:13-24); the manifest must record the resolved values used, not merely the script defaults.

8. Sign-off matrix

Signatory Required approval
Product Owner Supported product surface, canonical journeys, state/exception contracts, accepted limitations.
Commercial/package owner SKU ownership, dependencies, entitlement and optional-module boundaries.
Security owner Capability taxonomy, deny-by-default, elevation, tenant/record-scope test results.
DPO/privacy owner Sensitive data purpose, visibility, attachment/proof, retention, evidence redaction.
School SME / process owner Roles, prerequisites, completion, approval, correction/recovery, terminology.
Engineering owners FE/API/model consistency, fixes, regressions, build reproducibility.
QA owner Golden Tenant determinism, matrix completeness, results and absence of hidden skips.
Operations/SRE Install/upgrade, runtime config, health, monitoring, backup/restore, rollback.
Release owner All gates complete on the same manifest and no post-run drift.

No single signatory may waive a cross-tenant, security, privacy, or data-integrity failure. A waiver needs all relevant domain owners and still cannot override the non-waivable list in §2.1.

9. Freeze dan change control

After approval:

  1. tag/freeze exact FE and BE commits and archive the release manifest;
  2. freeze supported package/role/menu/route/capability/state/API contracts;
  3. derive the documentation source-of-truth from the passing traceability matrix;
  4. require impact analysis for every later code/config/schema/entitlement change;
  5. rerun affected tests plus all cross-cutting auth/tenant/package gates; and
  6. revoke GREEN when the served build, module state, or runtime config drifts from the manifest.

A copy change with no behavioral impact may use a bounded review. Any change to role, capability, route, menu, state, field requirement, mutation, downstream effect, tenant scope, or recovery invalidates the corresponding frozen evidence until tests pass again.

10. Current gate result

Gate family Current result Basis
Product contract BLOCKED Candidate scope exists, but supported classifications and critical decisions are not yet signed.
IA and UX BLOCKED Alias/menu/permission drift and placeholder/legacy surfaces remain; full closure evidence is absent.
Authorization and isolation BLOCKED Cross-cutting Blocker A findings remain open.
Golden Tenant NOT RUN Specification is part of this program; no deterministic three-run seed/reset evidence exists for this baseline.
Core E2E NOT RUN Static test files are not results tied to this exact release manifest.
Defects/decisions BLOCKED Existing register has open Blocker A/B and workshop decisions.
Regression/build/deploy NOT RUN This task intentionally does not execute or certify a release candidate.
Documentation freeze BLOCKED Production documentation remains paused until QG-01–QG-18 applicable gates pass.

Conclusion: the repository is suitable as input to a stabilization program, but it is not yet evidence of a Scola V1 Production Baseline. No module or workflow becomes GREEN from this planning audit alone.